Skip to content

Privacy policy

What PokéTrack does with your data

Last updated: August 10, 2026

1. Data controller

The data controller is Arnaud de Cuniac, a natural person, publisher of the PokéTrack service in a personal, non-professional capacity.

Contact: a.decuniac@gmail.com

Given the nature and volume of the processing involved, no data protection officer has been appointed.

2. Guiding principle

PokéTrack is a personal project. Only the data required to operate it is collected.

The Service carries no audience measurement, no advertising tracker and no behavioral analytics. Your data is never sold, rented or passed to third parties for commercial purposes, and is subject to no profiling and no automated decision-making.

3. Data collected

a. Account

Your name, your email address, whether that address has been verified, and the dates the account was created and last modified. If you sign in with a Google account, that account’s identifier and, where applicable, the profile picture address provided by Google.

b. Authentication material

The fingerprint of your password, stored hashed and never in clear text. The tokens issued by Google if you use that sign-in method, which may contain the email address of that Google account, along with the permissions granted to the Service. The one-time codes sent by email, stored hashed, along with address verification and password reset tokens.

During a Google sign-in or account link, a temporary technical state is also recorded: it holds the return address to the Service, a single-use security key and, in the case of a link, the email address and identifier of the account concerned.

c. Sessions

A session token and its expiry date, together with the IP address and browser identifier (user-agent) recorded when the session was opened.

d. Collection

The identifiers of the cards you declare you own, along with the date they were added. No data is retrieved from the game: this list comes solely from what you enter.

e. Preferences

Whether secret cards should be counted towards your progress.

f. Security

Request rate-limiting counters, stored under a key that pairs your IP address with the route called. An IPv4 address is kept whole; an IPv6 address is truncated to its first 64 bits, both here and for sessions.

No sensitive data within the meaning of Article 9 of the GDPR is collected. The Service processes no payment data, since it involves no payments.

PurposeData involvedLegal basis
Creating and managing your accounta, bPerformance of the contract formed by the terms of use
Authenticating you and keeping your session openb, cPerformance of the contract
Sending verification and password reset emailsaPerformance of the contract
Recording your collection and computing your progressd, ePerformance of the contract
Protecting the Service against abuse and intrusion attemptsc, fLegitimate interest in the security of the Service
Answering your requestsa and the content of your messageLegitimate interest in handling incoming inquiries

5. Emails sent

The only emails sent are transactional: address verification, password reset, and a notice when someone attempts to sign up with an address already tied to an account.

No newsletter and no promotional email is ever sent.

6. Cookies and local storage

The Service sets four cookies, all strictly necessary for it to work. As such they are exempt from prior consent, and no cookie banner is displayed.

CookieRoleLifetime
__Secure-better-auth.session_tokenKeeps your session open. Signed cookie, not readable by page JavaScript30 days
__Secure-better-auth.session_dataCaches the session to avoid a database read on every page5 minutes
__Secure-better-auth.stateProtects a Google sign-in or account link against request forgery5 minutes
i18n_redirectedRemembers the language you chose1 year

The __Secure- prefix is added by the authentication layer when the Service is served over HTTPS, which is the case in production. Outside HTTPS the first three cookies carry the same names without that prefix.

The Service also stores two pieces of information in your browser’s local storage: the cards most recently searched in the booster tool, under a key prefixed poketrack.recent-target-cards, and your theme preference (light, dark or system). This information is never sent to the server and disappears if you clear the site data.

7. Recipients and processors

Your data is only accessible to the publisher and to the following technical providers, acting on the publisher’s instructions:

ProviderRoleData involvedLocation
Vercel Inc.Site hosting and image deliveryData passing through the Service, technical logsUnited States, delivered through a global network
NeonDatabaseAccount, authentication, sessions, collection, preferencesEuropean Union
ResendSending transactional emailsName, email address, email contentUnited States
GoogleGoogle account sign-in, only if you choose that methodAuthentication materialUnited States

Your data may also be disclosed to an administrative or judicial authority where the law requires it.

8. Transfers outside the European Union

The database, which holds the bulk of your data, is hosted within the European Union.

The hosting, email and authentication providers are established in the United States. Transfers to those providers are governed by the standard contractual clauses adopted by the European Commission and, where applicable, by their adherence to the EU / US data protection framework.

9. Retention periods

DataPeriod
Account, collection and preferencesFor as long as the account exists. No automatic deletion is applied for inactivity
SessionsValid for 30 days, or until you sign out
One-time codes and reset tokensValid for 1 hour
Google sign-in and link statesValid for 10 minutes
Rate-limiting countersA few minutes
Emails you send to the publisherAs long as needed to handle your request

Once the stated period has passed, a session, a one-time code, a reset token or a sign-in state stops being valid and can no longer be used. The matching row is not erased automatically, however: it stays in the database until a cleanup is carried out.

Deleting your account, requested as described in section 10, erases the account itself, your sign-in credentials, your sessions, your collection and your preferences. Three technical sets are not tied to the account and therefore do not disappear with it: verification and reset codes, which hold the email address they were sent to; Google sign-in and link states, which hold the return address and, for a link, the email address and identifier of the account; and rate-limiting counters, which hold an IP address. You may ask for those to be erased in the same request. Residual copies may also remain for a few days in the host’s backups, before being overwritten in turn.

10. Your rights

Under the GDPR, you have the right to access, rectify, erase, restrict and object to the processing of your data, as well as the right to data portability and the right to set instructions on what becomes of your data after your death.

These rights are exercised by email to a.decuniac@gmail.com. You will receive a reply within a maximum of 30 days. A verification element may be requested if there is serious doubt about your identity.

If you believe your rights are not being respected, you may lodge a complaint with the French data protection authority, Commission nationale de l’informatique et des libertés, 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, or at www.cnil.fr.

11. Security

Exchanges with the Service are encrypted over HTTPS. Passwords and one-time codes are stored hashed. Session cookies are signed and not readable by page JavaScript. Every authentication route is rate limited, with tighter thresholds on sign-in, sign-up and password reset. Database access is restricted.

Since no system is infallible, and the Service is a personal project, no guarantee of absolute security can be given. If you discover a vulnerability, please write to the contact address rather than disclosing it publicly.

12. Minors

The Service is reserved for people aged 15 or over, in accordance with Article 5 of the terms of use. No data is knowingly collected from anyone younger. If such an account is reported, it is deleted and its data erased.

13. Changes

This policy may change, in particular if the way the Service works or the providers it relies on change. The date it was last updated appears at the top of the document.

In the event of a substantial change, users holding an account are informed by email or through a visible notice on the Service.

14. Language

This policy is written in French. The English translation is provided for information only: in the event of any discrepancy, the French version prevails.

PokéTrack

Track your Pokémon TCG Pocket collection.

All Pokémon images, names, characters and related trademarks are registered trademarks and the property of The Pokémon Company, Nintendo, Game Freak, Creatures Inc. or DeNA. This unofficial fan site is neither endorsed by nor affiliated with the Pokémon rights holders.

© 2026 PokéTrack

Game data and card artwork from the pokemon-tcg-pocket-database and pokemon-tcg-exchange projects